cso

Audit infrastructure and software supply chains for security risks.

Updated Mar 24, 2026
One-click install
npx skills add https://github.com/pistosmin/base-one --skill cso-pistosmin
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cso
Source: https://github.com/pistosmin/base-one/tree/main/.claude/skills/gstack/cso
Command: npx skills add https://github.com/pistosmin/base-one --skill cso-pistosmin

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode focuses on infrastructure-first security audits to uncover secrets, supply chain, and pipeline risks, providing continuous visibility into your security posture.

Core Features & Use Cases

  • Secrets archaeology, dependency supply chain analysis, and CI/CD pipeline security review.
  • LLM/AI security assessment, skill supply chain scanning, and OWASP Top 10 + STRIDE threat modeling.
  • Two modes: daily zero-noise checks and monthly comprehensive scans with trend tracking.

Quick Start

Run the cso audit workflow to start an infrastructure-first security posture assessment across your stack.

Frequently Asked Questions about cso

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my CI/CD pipeline and cloud infrastructure for security vulnerabilities?

To audit CI/CD pipeline and cloud infrastructure for security vulnerabilities, you need an infrastructure-first security review. This workflow scans your deployment pipelines and supply chains to identify risks, secrets, and OWASP/STRIDE threat vectors.

What is secrets archaeology and how does it secure my software supply chain?

Secrets archaeology is the process of uncovering hardcoded credentials and hidden secrets within your software supply chain. It scrutinizes dependencies and pipeline configurations to identify exposed sensitive data and secure your continuous deployment workflow.

Can I apply OWASP Top 10 and STRIDE threat modeling to AI-driven application components?

Yes, you can apply OWASP Top 10 and STRIDE threat modeling to AI-driven components. The security audit workflow assesses LLM integrations and AI-driven components to identify specific risks and verify your ongoing security posture.

What's the best way to run continuous security posture checks without alert fatigue?

The best way to run continuous security posture checks without alert fatigue is using a dual-mode scanning approach. A daily zero-noise check mode identifies critical active vulnerabilities, while a monthly comprehensive scan tracks security risk trends.

Does infrastructure-first security auditing require active verification of threats?

Yes, infrastructure-first security auditing includes active verification to confirm identified threats. It validates vulnerabilities across your cloud deployments and CI/CD pipelines through active checks rather than relying solely on static analysis.

When do I need a comprehensive security scan versus daily dependency supply chain scrutiny?

You need a comprehensive security scan for monthly trend tracking and full OWASP/STRIDE coverage, whereas daily dependency supply chain scrutiny provides zero-noise checks to catch immediate risks in your software pipeline.